What Is GDPR? Complete Guide to EU Data Protection (2026)

By Recording Law Editorial TeamReviewed September 11, 202623 min read
What Is GDPR? Complete Guide to EU Data Protection (2026)

Frequently Asked Questions

What does GDPR stand for?

GDPR stands for General Data Protection Regulation. It is Regulation (EU) 2016/679 of the European Parliament and of the Council, adopted on April 14, 2016, and enforceable since May 25, 2018. The regulation standardizes data protection law across all EU member states and the European Economic Area, replacing the 1995 Data Protection Directive.

Does the GDPR apply outside of Europe?

Yes. Article 3(2) gives the GDPR extraterritorial reach. An organization with no establishment in the EU must comply where it offers goods or services to people who are in the EU, or monitors their behavior as far as that behavior takes place within the Union, for example through website analytics, behavioral advertising, or tracking. Nationality and place of residence are irrelevant under Recital 14, so a visitor physically in the EU is covered, while an EU citizen living outside the Union may not be. A company in the United States, Canada, or Japan is subject to the GDPR when it processes the personal data of people in the EU in those contexts.

What are the seven principles of the GDPR?

The seven principles under Article 5 are: (1) lawfulness, fairness, and transparency; (2) purpose limitation; (3) data minimization; (4) accuracy; (5) storage limitation; (6) integrity and confidentiality (security); and (7) accountability. These principles apply to all processing of personal data. The accountability principle places the burden on the controller to demonstrate compliance with the other six.

What is the difference between a data controller and a data processor?

A controller decides the purposes and means of processing personal data and bears primary GDPR compliance responsibility. A processor handles personal data on behalf of the controller, following the controller's instructions. For example, a retailer (controller) that uses a cloud hosting provider (processor) to store customer data. Controllers and processors must enter into a written data processing agreement under Article 28.

What are the six lawful bases for processing?

Article 6 sets out six lawful bases: (1) consent of the data subject; (2) contractual necessity; (3) compliance with a legal obligation; (4) protection of vital interests; (5) performance of a task in the public interest or exercise of official authority; and (6) legitimate interests of the controller or a third party. Every processing activity must be justified under one of these bases before processing begins.

What are the maximum GDPR fines?

The highest tier of GDPR fines is EUR 20 million or 4% of total worldwide annual turnover from the preceding financial year, whichever is higher. This applies to violations of core principles, lawful bases, data subject rights, and international transfer rules. A lower tier of EUR 10 million or 2% applies to more procedural violations. As of September 2026 the largest single GDPR fine on record is EUR 1.2 billion, issued to Meta by Ireland's DPC in 2023 for unlawful data transfers, and that decision is still the subject of court proceedings.

What is the GDPR Procedural Regulation?

Regulation (EU) 2025/2518, known as the GDPR Procedural Regulation, was published in December 2025 and entered into force on January 1, 2026, with application from April 2, 2027. It introduces binding deadlines for cross-border enforcement cases (a 15-month investigation window, extendable by 12 months), standardized procedural rights for complainants and parties under investigation, and improved transparency. It does not change the substantive obligations in the GDPR itself.

What is the EU Digital Omnibus and how does it affect the GDPR?

The Commission tabled the Digital Omnibus on November 19, 2025 as two proposals. The AI limb was adopted as Regulation (EU) 2026/1744 and has been in force since 27 July 2026; it does not amend the GDPR. The data limb, COM(2025) 837, is the one that would amend the GDPR, and it is still a proposal: as of September 2026 the European Parliament Legislative Observatory lists it as awaiting committee decision. Its proposed GDPR changes include an abuse-of-rights ground in Article 12(5), narrower transparency duties in Article 13, breach notification in Article 33(1) only for high-risk breaches and within 96 hours through the NIS 2 single entry point, and changes to Articles 4, 5(1)(b), 9 and 22. The record-keeping relief for smaller organizations sits in a separate package, Omnibus IV, which is also not yet adopted. The current GDPR text remains in force.

When did the GDPR take effect?

The GDPR was adopted on April 14, 2016, published on May 4, 2016, and took effect on May 25, 2018, after a two-year transition period. It replaced the 1995 Data Protection Directive (Directive 95/46/EC). The GDPR was adopted on April 14, 2016 and became applicable on May 25, 2018. May 25, 2026 marked the eighth anniversary of the GDPR becoming applicable.

Updates

Corrected the Article 3(2) territorial-scope test to the statutory standard of people who are in the EU, restated the Digital Omnibus and EU AI Act items against the current EU texts, moved the Article 30 record-keeping change to Omnibus IV where it belongs, added the Article 27(2) representative exemptions and the Article 20 and Article 12(5) limits, attributed the cumulative-fines figure to its source, and replaced two dead official links

Expanded from 2,850 to approximately 4,800 words; added dedicated sections on data subject rights overview (Chapter III table), GDPR and national implementing laws, and Recent Developments (2024-2026) covering the GDPR Procedural Regulation (Regulation (EU) 2025/2518), the Digital Omnibus proposal (proposal only, not enacted), and EU AI Act interplay; updated enforcement statistics through early 2026 (EUR 7.1 billion cumulative, EUR 530M TikTok fine, EDPB 10th anniversary); added new FAQ entries; expanded citations to 23 sources. Several statements in that revision were found to be inaccurate and were corrected on 10 September 2026; see the later entries in this log

Initial publication

Sources and References

  1. GDPR Full Text — Regulation (EU) 2016/679(eur-lex.europa.eu).gov
  2. Directive 95/46/EC — 1995 Data Protection Directive(eur-lex.europa.eu).gov
  3. GDPR Consolidated Text (EUR-Lex)(eur-lex.europa.eu).gov
  4. European Data Protection Board (EDPB)(edpb.europa.eu).gov
  5. EDPB Guidelines 3/2018 on Territorial Scope (Article 3)(edpb.europa.eu).gov
  6. EDPB SME Guide - Data Protection Basics and the Key GDPR Principles(edpb.europa.eu).gov
  7. EDPB Guidelines 1/2024 on Legitimate Interests (Article 6(1)(f))(edpb.europa.eu).gov
  8. EDPB Guidelines 07/2020 — Controller and Processor(edpb.europa.eu).gov
  9. EDPB SME Guide — Data Controller vs Data Processor(edpb.europa.eu).gov
  10. EDPB SME Guide — Respecting Individuals Rights(edpb.europa.eu).gov
  11. EDPB and EDPS Joint Opinion on Digital Omnibus (2026)(edpb.europa.eu).gov
  12. EDPB — Marking 10 Years of the GDPR (2026)(edpb.europa.eu).gov
  13. EDPS — History of the GDPR(edps.europa.eu).gov
  14. European Commission — Principles of the GDPR(commission.europa.eu).gov
  15. European Commission - Application of the GDPR (roles of controller and processor)(commission.europa.eu).gov
  16. European Commission — Data Protection Explained(commission.europa.eu).gov
  17. European Commission — Adequacy Decisions(commission.europa.eu).gov
  18. European Commission — Data Protection in the EU(commission.europa.eu).gov
  19. ICO — Guide to the Data Protection Principles(ico.org.uk).gov
  20. Article 3 GDPR — Territorial Scope(gdpr-info.eu)
  21. Article 5 GDPR — Principles(gdpr-info.eu)
  22. Article 6 GDPR — Lawfulness of Processing(gdpr-info.eu)
  23. GDPR Chapter 3 — Rights of the Data Subject(gdpr-info.eu)
  24. Regulation (EU) 2025/2518 - GDPR Procedural Regulation (EUR-Lex)(eur-lex.europa.eu).gov
  25. Regulation (EU) 2026/1744 - Digital Omnibus on AI (EUR-Lex)(eur-lex.europa.eu).gov
  26. Regulation (EU) 2024/1689 - EU Artificial Intelligence Act (EUR-Lex)(eur-lex.europa.eu).gov
  27. COM(2025) 837 - Digital Omnibus proposal, data limb (EUR-Lex)(eur-lex.europa.eu).gov
  28. European Parliament Legislative Observatory - procedure 2025/0360(COD)(oeil.europarl.europa.eu).gov
  29. Omnibus IV provisional agreement PE790.249, 26 June 2026 (European Parliament)(europarl.europa.eu).gov
  30. European Parliament Legislative Observatory - procedure 2025/0130(COD), Omnibus IV(oeil.europarl.europa.eu).gov
  31. Irish DPC - TikTok EUR 530 million decision and corrective measures(dataprotection.ie).gov
  32. Irish DPC - index of court judgments in DPC proceedings(dataprotection.ie).gov
  33. Ireland - Data Protection Act 2018, section 31 (digital age of consent)(irishstatutebook.ie).gov
  34. Spain - Ley Organica 3/2018, Article 7 (consent of minors)(boe.es).gov
  35. DLA Piper - GDPR Fines and Data Breach Survey, January 2026(dlapiper.com)
  36. CMS GDPR Enforcement Tracker - statistics(enforcementtracker.com)
Share: